Posted by the organisation on ReliefWeb · Verified employer
Information Security Analyst
IDinsight
Job at a glance
- Employer
- IDinsight
- Position
- Information Security Analyst
- Location
- India, Kenya, Morocco, Philippines, Senegal, Zambia
- Salary
- Not stated in the advert
- Application deadline
- 15 October 2026
- Posted on VacancyKE
- 15 September 2026
VacancyKE summary
IDinsight is hiring an Information Security Analyst to work in India, Kenya, Morocco, the Philippines, Senegal or Zambia. You will manage security tools, handle incidents and support data protection compliance across a global team.
What’s offered
- Comprehensive international health insurance with mental health coverage.
- Paid vacation, sick and parental leave.
- Relocation benefits.
- Travel stipend.
- Technology and work-from-home stipends.
- Professional development budget.
- Employment visa sponsorship for all nationalities in the listed locations.
- Support towards CISM or CISSP certification.
Key responsibilities
- Administer the security stack including SASE, CASB, EDR, SIEM and MDM, tuning policies and investigating alerts.
- Design and run security education, training and awareness programmes across the organisation.
- Triage and investigate security events, coordinate containment and maintain the incident response plan.
- Conduct information and data security risk assessments on projects, systems, vendors and data flows.
- Respond to security and data protection due diligence requests from funders, government partners and clients.
- Develop and maintain information security policies, standards and practical guidelines.
- Support GDPR and national data protection compliance including data mapping, retention and subject rights requests.
- Contribute to the control framework, maintain the risk register and support assurance activity.
- Help govern AI use on project and organisational data through tool assessment and acceptable use guidance.
- Occasionally provide systems support via the internal help desk.
Key requirements
- 3–5 years of professional experience in information security, IT security operations or a closely related role.
- Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM and MDM.
- Demonstrated experience in incident response, including investigation and post-incident reporting.
- Experience conducting information or data security risk assessments and communicating findings to non-technical audiences.
- Experience developing information security policies, standards or guidelines that were adopted and used.
- Working knowledge of GDPR and at least one national data protection law such as Kenya's, Zambia's or India's DPDP Act.
- Familiarity with recognised information security standards and frameworks such as NIST SP 800-171, NIST CSF or ISO/IEC 27001.
- A bachelor's degree in Computer Science or other quantitative disciplines.
- Strong communicator in written communications, public speaking, teamwork and upward management.
- Ability to work with international, cross-cultural and diverse teams across time zones.
Nice to have
- A security certification such as Security+ or SSCP.
- Demonstrated interest in IT governance, risk, compliance and AI governance.
How to apply
- Start date is as soon as possible, with preference for candidates who can start immediately.
- A minimum two-year commitment is expected.
- Candidates not currently located in the listed country offices must relocate there at the onset of employment.
- Candidates who do not require visa sponsorship are prioritised.
Official source: Posted by the organisation on ReliefWeb · reliefweb.int. VacancyKE never charges job seekers.
Original employer advertisement
Published by IDinsight on reliefweb.int. Shown for reference; the employer’s version is the official one.
The employer’s advert
**About the Information Security Analyst Role**
The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams to achieve social impact. This role will be a great fit for someone who is genuinely hands-on with security tooling, who can write clearly enough that a policy actually changes behaviour, and who would rather reduce risk at the design stage than document it after the fact.
**Responsibilities**
As an Information Security Analyst, your core day-to-day work may include:
- **Security tooling administration** — Owning day-to-day administration of our security stack, including SASE, CASB, EDR, SIEM, and MDM. Tuning policies and detections, maintaining coverage across a distributed fleet, investigating alerts, and keeping the tooling useful rather than merely deployed.
- **Security Education, Training and Awareness** — Designing and running SETA across the organisation: onboarding security training, phishing simulations, targeted sessions for higher-risk teams, and awareness material that colleagues in six offices actually read.
- **Incident response** — Triaging and investigating security events, coordinating containment and recovery, maintaining and exercising the incident response plan, and writing up what happened and what changes as a result.
- **Risk assessment** — Conducting information and data security risk assessments on projects, systems, vendors, and data flows. Translating findings into recommendations that project teams can act on within their timelines.
- **Partner due diligence** — Responding to security and data protection due diligence requests from funders, government partners, and clients, and maintaining the evidence library so each response is faster than the last.
- **Policy and guidance** — Developing and maintaining information security policies, standards, and practical guidelines, and keeping them aligned with recognised frameworks and with our regulatory obligations.
- **Data protection compliance** — Supporting compliance with GDPR and the national data protection regimes in the countries where we operate: data mapping, retention, subject rights requests, and the assessments that new processing activities require.
- **Governance, risk, and compliance** — Contributing to the control framework, maintaining the risk register, and supporting internal and external assurance activity.
- **AI governance** — Contributing to how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use guidance, and the controls that make responsible use the default.
**Professional Growth and Internal Contributions**
Beyond your core responsibilities, you will contribute to the Information Security and Systems team and your own professional development through:
- **Systems Support:** You will occasionally provide Systems Support via our internal help desk. This gives you direct insight into the technical challenges IDinsighters face and lets you deliver high-impact solutions.
- **Continuous Learning:** IDinsight utilises a diverse ecosystem of tools. While we don't expect day-one mastery of every system, we look for a commitment to building deep technical expertise over time. We support security certification and continuing professional education.
**Qualifications**
We're looking for an entrepreneurial, “get stuff done” teammate with 3–5 years of relevant experience. Desired qualifications include:
- 3–5 years of professional experience in information security, IT security operations, or a closely related role;
- Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM, and MDM, and the ability to get productive on the rest;
- Demonstrated experience in incident response, including investigation and post-incident reporting;
- Experience conducting information or data security risk assessments and communicating findings to non-technical audiences;
- Experience developing information security policies, standards, or guidelines that were adopted and used;
- Working knowledge of GDPR and of at least one national data protection law in the regions where we operate, such as Kenya's Data Protection Act, Zambia's Data Protection Act, or India's DPDP Act;
- Familiarity with recognised information security standards and frameworks, such as NIST SP 800-171, NIST CSF, or ISO/IEC 27001;
- A security certification is valued — Security+ or SSCP at this level, with CISM or CISSP as a credible next step we will support you toward;
- Demonstrated interest in IT governance, risk, and compliance, and in AI governance;
- A bachelor's degree in Computer Science or other quantitative disciplines;
- Strong communicator in multiple forms (written communications, public speaking, teamwork, and upward management), with a track record of explaining risk to people who have competing priorities;
- Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
- Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
- Strong desire for professional growth and development, with a track record of openness to give and receive feedback;
- Strong problem-solving skills in handling system challenges;
- People-focused and people-facing, with high levels of empathy and desire to listen to and share in teammates' victories, concerns, and needs;
- Strong ability to maintain integrity and confidentiality in complex situations;
- Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
- Ability to work with international, cross-cultural, and diverse teams across time zones.
**Nuts & bolts**
**Start date**
The start date for this position is as soon as possible, with preference given to candidates who can start immediately. We expect a minimum two-year commitment, with regular professional development conversations and the potential for a long-term career at IDinsight.
**Work Authorization**
IDinsight is able to sponsor employment visas for all nationalities in the locations listed above; however, we will prioritize candidates who do not require IDinsight to sponsor work authorization in the aforementioned countries. All candidates who are not currently located in our country offices listed above will be expected to relocate to their office locations at the onset of their employment.
**Compensation**
Compensation and benefits are commensurate with the qualifications and experiences IDinsight is hiring for, and competitive within the global development sector. We are especially proud of the people-focused benefits we offer, including comprehensive international health insurance with mental health coverage; paid vacation, sick, and parental leave; relocation benefits; a travel stipend; technology and work-from-home stipends; a professional development budget; and more. Please note that, as a non-profit, we are unable to provide compensation similar to leading private sector organizations.
**IDinsight’s commitment to reducing power asymmetries**
IDinsight is committed to reducing power asymmetries in the social sector. Our commitment to diversity, equity, and inclusion reflects our understanding of the need for the sector to abandon unhealthy practices of the past. We wish to be part of a new generation of international NGOs who are honest about this history and transparent about our role in the present. Our commitment is also aligned with the impact of our work.
We seek a workforce that is inclusive of a variety of perspectives that will help us refine and improve our methods and relationships, and strengthen the services we provide our clients and their communities or constituencies. The following commitments represent our vision for the IDinsight team:
1. IDinsight will have greater representation from the **populations with whom we work** and **clients we serve**.
2. IDinsight will have greater representation from the **countries in which we work**.
3. Across all countries in which we recruit, we will seek **greater representation from historically excluded communities**.
4. IDinsight will foster an **inclusive work culture that empowers a diverse team** to do their best work.
IDinsight is committed to non-discrimination in our recruitment, employment practices, and organizational culture, regardless of people's age, disability, gender, gender identity, national origin, race, religion or belief, or sexual orientation, or any other status protected by applicable law.
The Information Security and Systems team is the engine driving our uniquely dynamic, high-achieving, multicultural, multi-continental team at the cutting edge of how evidence is used to improve global development programs. This team's mandate is to build and maintain systems that enable IDinsight teams to achieve social impact. This role will be a great fit for someone who is genuinely hands-on with security tooling, who can write clearly enough that a policy actually changes behaviour, and who would rather reduce risk at the design stage than document it after the fact.
**Responsibilities**
As an Information Security Analyst, your core day-to-day work may include:
- **Security tooling administration** — Owning day-to-day administration of our security stack, including SASE, CASB, EDR, SIEM, and MDM. Tuning policies and detections, maintaining coverage across a distributed fleet, investigating alerts, and keeping the tooling useful rather than merely deployed.
- **Security Education, Training and Awareness** — Designing and running SETA across the organisation: onboarding security training, phishing simulations, targeted sessions for higher-risk teams, and awareness material that colleagues in six offices actually read.
- **Incident response** — Triaging and investigating security events, coordinating containment and recovery, maintaining and exercising the incident response plan, and writing up what happened and what changes as a result.
- **Risk assessment** — Conducting information and data security risk assessments on projects, systems, vendors, and data flows. Translating findings into recommendations that project teams can act on within their timelines.
- **Partner due diligence** — Responding to security and data protection due diligence requests from funders, government partners, and clients, and maintaining the evidence library so each response is faster than the last.
- **Policy and guidance** — Developing and maintaining information security policies, standards, and practical guidelines, and keeping them aligned with recognised frameworks and with our regulatory obligations.
- **Data protection compliance** — Supporting compliance with GDPR and the national data protection regimes in the countries where we operate: data mapping, retention, subject rights requests, and the assessments that new processing activities require.
- **Governance, risk, and compliance** — Contributing to the control framework, maintaining the risk register, and supporting internal and external assurance activity.
- **AI governance** — Contributing to how IDinsight governs AI use on project and organisational data: tool assessment, acceptable use guidance, and the controls that make responsible use the default.
**Professional Growth and Internal Contributions**
Beyond your core responsibilities, you will contribute to the Information Security and Systems team and your own professional development through:
- **Systems Support:** You will occasionally provide Systems Support via our internal help desk. This gives you direct insight into the technical challenges IDinsighters face and lets you deliver high-impact solutions.
- **Continuous Learning:** IDinsight utilises a diverse ecosystem of tools. While we don't expect day-one mastery of every system, we look for a commitment to building deep technical expertise over time. We support security certification and continuing professional education.
**Qualifications**
We're looking for an entrepreneurial, “get stuff done” teammate with 3–5 years of relevant experience. Desired qualifications include:
- 3–5 years of professional experience in information security, IT security operations, or a closely related role;
- Hands-on administration experience with at least three of SASE, CASB, EDR, SIEM, and MDM, and the ability to get productive on the rest;
- Demonstrated experience in incident response, including investigation and post-incident reporting;
- Experience conducting information or data security risk assessments and communicating findings to non-technical audiences;
- Experience developing information security policies, standards, or guidelines that were adopted and used;
- Working knowledge of GDPR and of at least one national data protection law in the regions where we operate, such as Kenya's Data Protection Act, Zambia's Data Protection Act, or India's DPDP Act;
- Familiarity with recognised information security standards and frameworks, such as NIST SP 800-171, NIST CSF, or ISO/IEC 27001;
- A security certification is valued — Security+ or SSCP at this level, with CISM or CISSP as a credible next step we will support you toward;
- Demonstrated interest in IT governance, risk, and compliance, and in AI governance;
- A bachelor's degree in Computer Science or other quantitative disciplines;
- Strong communicator in multiple forms (written communications, public speaking, teamwork, and upward management), with a track record of explaining risk to people who have competing priorities;
- Detail- and execution-oriented, able to take a task from high-level strategic idea to rapid execution with a large amount of autonomy and conscientiousness;
- Demonstrated track record as a self-starter and leader, including comfort with ambiguity and dynamic environments and work streams;
- Strong desire for professional growth and development, with a track record of openness to give and receive feedback;
- Strong problem-solving skills in handling system challenges;
- People-focused and people-facing, with high levels of empathy and desire to listen to and share in teammates' victories, concerns, and needs;
- Strong ability to maintain integrity and confidentiality in complex situations;
- Ability to handle sensitive information, data, and issues with mature and discreet professionalism;
- Ability to work with international, cross-cultural, and diverse teams across time zones.
**Nuts & bolts**
**Start date**
The start date for this position is as soon as possible, with preference given to candidates who can start immediately. We expect a minimum two-year commitment, with regular professional development conversations and the potential for a long-term career at IDinsight.
**Work Authorization**
IDinsight is able to sponsor employment visas for all nationalities in the locations listed above; however, we will prioritize candidates who do not require IDinsight to sponsor work authorization in the aforementioned countries. All candidates who are not currently located in our country offices listed above will be expected to relocate to their office locations at the onset of their employment.
**Compensation**
Compensation and benefits are commensurate with the qualifications and experiences IDinsight is hiring for, and competitive within the global development sector. We are especially proud of the people-focused benefits we offer, including comprehensive international health insurance with mental health coverage; paid vacation, sick, and parental leave; relocation benefits; a travel stipend; technology and work-from-home stipends; a professional development budget; and more. Please note that, as a non-profit, we are unable to provide compensation similar to leading private sector organizations.
**IDinsight’s commitment to reducing power asymmetries**
IDinsight is committed to reducing power asymmetries in the social sector. Our commitment to diversity, equity, and inclusion reflects our understanding of the need for the sector to abandon unhealthy practices of the past. We wish to be part of a new generation of international NGOs who are honest about this history and transparent about our role in the present. Our commitment is also aligned with the impact of our work.
We seek a workforce that is inclusive of a variety of perspectives that will help us refine and improve our methods and relationships, and strengthen the services we provide our clients and their communities or constituencies. The following commitments represent our vision for the IDinsight team:
1. IDinsight will have greater representation from the **populations with whom we work** and **clients we serve**.
2. IDinsight will have greater representation from the **countries in which we work**.
3. Across all countries in which we recruit, we will seek **greater representation from historically excluded communities**.
4. IDinsight will foster an **inclusive work culture that empowers a diverse team** to do their best work.
IDinsight is committed to non-discrimination in our recruitment, employment practices, and organizational culture, regardless of people's age, disability, gender, gender identity, national origin, race, religion or belief, or sexual orientation, or any other status protected by applicable law.